Free software under the Cyber Resilience Act
On 27 July 2026 the Commission published its guidance on applying the Cyber Resilience Act. Chapter 3 devotes fifty paragraphs to free and open-source software, setting out two cumulative conditions for a project to count as FOSS under the regulation, where the line falls between contributing and being answerable, and which obligations reach foundations and stewards depending on the support they provide.
Read more